Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-59391

Опубликовано: 08 дек. 2025
Источник: debian

Описание

A memory disclosure vulnerability exists in libcoap's OSCORE configuration parser in libcoap before release-4.3.5-patches. An out-of-bounds read may occur when parsing certain configuration values, allowing an attacker to infer or read memory beyond string boundaries in the .rodata section. This could potentially lead to information disclosure or denial of service.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libcoap3fixed4.3.5-2package
libcoap3fixed4.3.4-1.1+deb13u2trixiepackage
libcoap3no-dsabookwormpackage

Примечания

  • https://github.com/obgm/libcoap/pull/1730

  • Fixed by: https://github.com/obgm/libcoap/commit/da534de75edd1b3628a28908d30b0efbaa01be09 (develop)

  • Fixed by: https://github.com/obgm/libcoap/commit/d56fb48bffd625f779eaf4616ccda62e1a7f6fd3 (v4.3.5a)

Связанные уязвимости

CVSS3: 6.5
ubuntu
2 месяца назад

A memory disclosure vulnerability exists in libcoap's OSCORE configuration parser in libcoap before release-4.3.5-patches. An out-of-bounds read may occur when parsing certain configuration values, allowing an attacker to infer or read memory beyond string boundaries in the .rodata section. This could potentially lead to information disclosure or denial of service.

CVSS3: 6.5
nvd
2 месяца назад

A memory disclosure vulnerability exists in libcoap's OSCORE configuration parser in libcoap before release-4.3.5-patches. An out-of-bounds read may occur when parsing certain configuration values, allowing an attacker to infer or read memory beyond string boundaries in the .rodata section. This could potentially lead to information disclosure or denial of service.

CVSS3: 6.5
github
2 месяца назад

A memory disclosure vulnerability exists in libcoap's OSCORE configuration parser in libcoap before release-4.3.5-patches. An out-of-bounds read may occur when parsing certain configuration values, allowing an attacker to infer or read memory beyond string boundaries in the .rodata section. This could potentially lead to information disclosure or denial of service.